Debian 8 Jessie archive.debian.org GPG密钥过期问题求助
Debian 8 Jessie apt-get update GPG过期密钥问题解答
问题背景
自2022年11月19日起,Debian 8 Jessie执行apt-get update时出现GPG错误:
W: GPG error: http://archive.debian.org jessie Release: The following signatures were invalid: KEYEXPIRED 1587841717
当前sources.list配置:
deb http://archive.debian.org/debian/ jessie main contrib non-free deb http://deb.freexian.com/extended-lts jessie-lts main contrib non-free
已过期的密钥信息:
/etc/apt/trusted.gpg.d/debian-archive-jessie-automatic.gpg pub 4096R/2B90D010 2014-11-21 [expired: 2022-11-19] uid Debian Archive Automatic Signing Key (8/jessie) <ftpmaster@debian.org> /etc/apt/trusted.gpg.d/debian-archive-jessie-security-automatic.gpg pub 4096R/C857C906 2014-11-21 [expired: 2022-11-19] uid Debian Security Archive Automatic Signing Key (8/jessie) <ftpmaster@debian.org>
尝试从keyring.debian.org更新密钥失败:
gpg: requesting key 2B90D010 from hkp server keyring.debian.org gpgkeys: key 2B90D010 can't be retrieved gpg: no valid OpenPGP data found. gpg: Total number processed: 0 gpg: requesting key C857C906 from hkp server keyring.debian.org gpgkeys: key C857C906 can't be retrieved gpg: no valid OpenPGP data found. gpg: Total number processed: 0
问题解答
1. 密钥服务器keyring.debian.org是否正确?
是正确的Debian官方密钥服务器,但这两个过期的Jessie签名密钥已被移除。因为Debian 8 Jessie的所有支持周期(包括标准支持和Extended LTS)早已结束,官方不会再保留这类过期且不再使用的密钥在服务器上。
2. Debian官方是否会修复并发布新密钥?
不会。Debian 8 Jessie的标准支持在2018年6月结束,Extended LTS支持也在2022年6月终止,官方不会再为已停止支持的系统提供任何更新,包括新的签名密钥。
3. 如何消除apt-get update和install的警告?
有两种可行方案,需注意:关闭GPG验证会失去包完整性和来源真实性的保护,仅建议在无法升级系统的情况下临时使用。
方案一:修改sources.list跳过验证
在每个deb行开头添加[trusted=yes],修改后的sources.list如下:
deb [trusted=yes] http://archive.debian.org/debian/ jessie main contrib non-free deb [trusted=yes] http://deb.freexian.com/extended-lts jessie-lts main contrib non-free
修改后执行apt-get update即可消除警告。
方案二:全局关闭GPG检查
在/etc/apt/apt.conf.d/目录下新建配置文件(比如99-skip-gpg),写入以下内容:
Acquire::Check-Valid-Until "false"; APT::Get::AllowUnauthenticated "true";
保存后执行apt-get update即可生效。
内容的提问来源于stack exchange,提问作者StreNL
相关产品推荐
相关产品推荐

